
TARLOGIC's BLOG
Cybersecurity - Page 3
Cybersecurity articles with security analysis and ethical hacking technics information

Critical vulnerabilities of the ownCloud platform are being exploited in the wild
On November 21, 2023, three critical vulnerabilities were made public (CVE-2023-49103, CVE-2023-49104, CVE-2023-49105), affecting several applications of the ownCloud online file s[...]
Read more
CVE-2023-4911: The vulnerability Looney Tunables in GlibC is being actively exploited
On October 3, 2023, Qualys published information about a high-severity local privilege escalation vulnerability in the GNU C Library (glibc), which is widely used on Linux systems.[...]
Read more
CVE-2023-38545: Heap overflow vulnerability in curl (SOCKS 5)
The vulnerability CVE-2023-38545 affects curl, a command line tool and software library used to transfer data to and from a server On October 11th, 2023 the curl development team h[...]
Read more
CVE-2023-42115: Vulnerabilities without security patch in Exim
Exim has multiple critical vulnerabilities, including CVE-2023-4863, that allow attackers to run code on affected systems without authentication. Multiple vulnerabilities, one of t[...]
Read more
Bluetooth vulnerabilities in smart locks
Detecting and mitigating Bluetooth vulnerabilities in smart locks is critical to securing these IoT devices A smart lock is an IoT device that facilitates access by opening a door [...]
Read more
Hardware vulnerabilities in smart locks
We evaluate the hardware security level of the smart locks, disassembling one and analyzing the elements that make it up We got our hands on a Yale Linus smart lock, one that you c[...]
Read more
CVE-2023-4863: Heap buffer overflow in Google libwebp (WebP)
The vulnerability CVE-2023-4863 is found in the open source Libwebp library and affects browsers such as Mozilla, Chrome and Edge On September 6th, 2023 Apple Security Engineering [...]
Read more
CVE-2023-35082: Unauthenticated API Access Vulnerability in MobileIron Core
CVE-2023-35082 is a critical vulnerability that allows access to APIs in older versions of MobileIron Core Ivanti is having a tough time as another critical vulnerability has been [...]
Read more
CVE-2023-35078: Remote authentication bypass in Ivanti EPMM API
CVE-2023-35078 is a critical vulnerability that allows access to restricted functionality of Ivanti mobile management software A new critical vulnerability has been discovered in I[...]
Read more
CVE-2023-3519: 0-day vulnerability exploited the wild in Citrix NetScaler
On July 18, 2023, Citrix released information and updates to address a critical vulnerability (CVE-2023-3519) in NetScaler ADC and NetScaler Gateway. This vulnerability allows un[...]
Read more